deadband logodeadband
Two surfaces, one engine

About

deadband ships as a managed cloud at app.deadband.org and as a single-binary, MIT-licensed CLI on GitHub. Same probe code, same advisory matcher — pick whichever fits how you operate.

The problem

Firmware vulnerability assessment shouldn't require a six-figure platform.

Commercial OT vulnerability platforms bundle firmware gap analysis behind dedicated appliances, sensor networks, and annual contracts. For the vast majority of OT operators — small manufacturers, municipal utilities, facilities teams, even the OT side of larger enterprises that don't want a separate procurement track — the complexity is disproportionate to the task.

deadband takes a different approach. Discover devices on the network, cross-reference firmware against 3,600+ public CISA advisories, enrich with KEV and EPSS exploit intelligence, and surface what matters. The cloud product runs that pipeline continuously across one or many sites with a hosted dashboard, scheduled scans, and an audit log. The CLI runs the same pipeline as a single binary on your laptop or in a CI job — offline-capable, no account needed.

The advisory data comes from CISA's public CSAF repository. The KEV catalog and EPSS scores are freely available. deadband connects these into a coherent assessment pipeline — and gives you both an open-source way to use it and a managed way to use it.

When the cloud, when the CLI

They aren't a free vs. paid tier — they're different operating modes for different jobs.

The cloud

app.deadband.org

Lightweight agents installed on hosts inside your network discover devices on demand or on a recurring cadence and report findings into a hosted dashboard. The advisory matcher re-runs daily as new CISA disclosures land, so a device you scanned yesterday picks up tomorrow's advisories without re-scanning.

Best for production OT fleets — multi-site rollouts, teams that need an audit trail, anyone who wants the matcher to keep working after the initial assessment.

The CLI

MIT · open source

Single binary, no runtime dependencies, no account. Runs on a laptop on the plant floor, on a Raspberry Pi inside a control cabinet, or in a CI pipeline that scans an air-gapped pcap capture. Five output formats and meaningful exit codes for scripted use.

Best for evaluations, regulated air-gap environments, point-in-time pentest engagements, and anyone who doesn't want a SaaS dependency in the picture.

Design philosophy

Principles that hold across both products because the engine is the same code.

Read-only by construction

Discovery uses identity reads and port probes only. No CIP writes, no S7 writes, no engineering-mode commands — ever. The same probe code runs whether you launched it from the cloud agent or the CLI.

Public CISA data only

Advisory data comes from CISA's public CSAF repository (TLP:WHITE). KEV catalog and EPSS scores are freely available. No proprietary feeds, no black-box scoring — every match is reproducible from the inputs.

Conservative defaults

The agent claims one job at a time, dispatches only when initiated by an operator or a schedule, and posts findings in audited batches. The CLI prints a safety banner on startup. Neither runs anything resembling a control-plane action.

Transparent matcher

The matching engine is open source — vendor normalization, model pattern matching, semver + prose version comparison. You can replay any verdict against the same advisory snapshot and get the same answer.

Vendor coverage

Top vendors by CISA advisory count, with native protocol support for active and passive discovery.

VendorAdvisoriesDiscovery Protocol
Siemens979S7comm + OPC UA
Rockwell Automation229CIP/EIP
Schneider Electric224Modbus TCP
Hitachi Energy / ABB167Modbus TCP
Mitsubishi Electric115MELSEC/SLMP
Delta Electronics94Modbus TCP
Advantech78Modbus TCP / HTTP
Moxa48Modbus TCP / HTTP
Honeywell35BACnet/IP
Emerson / GE62Modbus TCP + GE-SRTP
Yokogawa30Modbus TCP
Omron28FINS
Beckhoff15OPC UA
Phoenix Contact23Modbus TCP
WAGO11Modbus TCP

Open core. Managed cloud. Pick your operating model.

The CLI is MIT-licensed with no telemetry — download it, fork it, build it into your own toolchain. The cloud is the same engine run by us, with a free tier sized for evaluations and homelabs.